Home security system flagged own photo app as attack due to 404 burst
A homelab user discovered on September 21 that their CrowdSec security system had flagged a single local alert. The alert was triggered by their own phone's photo-backup app requesting thumbnails for deleted photos. A burst of 11 requests returning 404 errors within four seconds resembled probing behavior to the detector. The investigation revealed that high metrics counts originated from shared community blocklists, not actual attacks on the local network. This highlighted the importance of distinguishing between local alerts and pre-emptive blocklist data.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in